Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook ingests malware indicators from Intel 471's Titan or Verity API into Microsoft Sentinel as tiIndicator resource type.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Intel471 |
| Source | View on GitHub |
This playbook uses 4 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azureblob |
Managed | 1 | 5 |
azuresentinel |
Managed | 1 | 1 |
keyvault |
Managed | 1 | 2 |
http |
Built-in | 0 | 1 |
azureblob (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| StoreCursor | put | /v2/datasets/@{uriComponent(uriComponent(parameters('StorageAccountName')))}/files/@{uriComponent(uriComponent(parameters('StorageAccountContainerName'),'/',parameters('BlobNameCursor')))} |
— |
| GetCursorFromBlob | get | /v2/datasets/@{uriComponent(uriComponent(parameters('StorageAccountName')))}/files/@{uriComponent(uriComponent(parameters('StorageAccountContainerName'),'/',parameters('BlobNameCursor')))}/content |
— |
| GetFromDateFromBlob | get | /v2/datasets/@{uriComponent(uriComponent(parameters('StorageAccountName')))}/files/@{uriComponent(uriComponent(parameters('StorageAccountContainerName'),'/',parameters('BlobNameFromDate')))}/content |
— |
| CreateBlobForCursor | post | /v2/datasets/@{uriComponent(uriComponent(parameters('StorageAccountName')))}/files |
— |
| CreateBlobForFromDate | post | /v2/datasets/@{uriComponent(uriComponent(parameters('StorageAccountName')))}/files |
— |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Threat_Intelligence_-Upload_STIX_Objects(Preview) | post | /ThreatIntelligence/@{encodeURIComponent(uriComponent(parameters('WorkspaceID')))}/UploadStixObjects/ |
— |
keyvault (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| GetApiKey | get | /secrets/@{encodeURIComponent(parameters('ApiKeySecretName'))}/value |
— |
| GetUsername | get | /secrets/@{encodeURIComponent(parameters('UsernameSecretName'))}/value |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| HTTP | GET | @parameters('ApiURI') |
— |
📄 Source: Intel471-ImportMalwareIntelligenceToSentinel/readme.md
This playbook fetches malware intelligence indicators from the Intel 471's Titan or Verity API and ingests them using Threat Intelligence UploadStixObjects API for Microsoft Sentinel.
azuredeploy.json Azure Resource Manager template (ARM template) is responsible for building the Logic App along with the necessary connections. The ARM builds following components:
ThreatIntelIndicators table using UploadStixObjects API.Note: installing the Intel 471 solution from the Microsoft Sentinel Content hub does not create the logic app. The solution installs the playbook templates; the logic app is created when you deploy a playbook from
Content hub→Intel 471→Manage→Create playbook, or fromMicrosoft Sentinel→Automation→Playbook templates. Deploying azuredeploy.json directly, as described below, creates it in one step.
An active account in Titan or Verity platform, which is available as part of Intel 471's subscriptions. For more information, please contact sales@intel471.com.
Titan or Verity API credentials - see Getting your Intel 471 API credentials.
Pre-existing Key Vault for securely storing the API credentials. By default the playbook reads:
| Backend | User name secret | API key secret |
| ------- | ---------------- | -------------- |
| Titan | TitanUserNameSentinel | TitanAPIKeySentinel |
| Verity | VerityUserNameSentinel | VerityAPIKeySentinel |
If your organisation already stores these credentials under different names, leave the secrets where they are and
pass the names of those secrets in the optional KeyVaultUsernameSecretName and KeyVaultApiKeySecretName
deployment parameters instead. Those two parameters take secret names, never credential values.
Pre-existing Storage account with a blob container, for persisting data such as the cursor between API calls. Default settings are fine - see Storage account requirements.
Threat Intelligence connector enabled in Sentinel. Go to Sentinel instance → Content hub and install Threat Intelligence solution.
The playbook authenticates to the Intel 471 API with HTTP Basic authentication. Which two values you need depends on the backend you select at deployment.
Backend = Verity)Verity issues an API Client ID and an API Client Secret. There is no separate "user name" or "API key" to look for - the Client ID is sent as the Basic user name and the Client Secret as the Basic password. Store them like this:
| Verity portal value | Key Vault secret (default name) |
|---|---|
| API Client ID | VerityUserNameSentinel |
| API Client Secret | VerityAPIKeySentinel |
To obtain them, sign in to the Intel 471 portal, open your account/API settings and create an API client.
Copy the Client Secret at creation time - it is not shown again. If you do not see the option, or the
indicators stream returns 403, your subscription may not include API access; contact
support@intel471.com.
Backend = Titan)Titan uses your account email as the Basic user name and an API key as the Basic password. Generate the API key at portal.intel471.com/api.
[Content truncated...]
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊